vendor:
N/A
by:
Tavis Ormandy and wvu
7.8
CVSS
HIGH
Command Execution
N/A
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: CVE-2018-16509
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-16863/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-16863/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-16863/, https://www.rapid7.com/db/vulnerabilities/ghostscript-cve-2018-16863/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2018-16863/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2018-16863/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp5-cve-2018-16863/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp5-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/ghostscript-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-16802/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-16802/, https://www.rapid7.com/db/?q=CVE-2018-16509&type=&page=2, https://www.rapid7.com/db/?q=CVE-2018-16509&type=&page=2
Other Scripts:
N/A
Platforms Tested: Unix, Linux, Windows
2018
Ghostscript Failed Restore Command Execution
This module exploits a -dSAFER bypass in Ghostscript to execute arbitrary commands by handling a failed restore (grestore) in PostScript to disable LockSafetyParams and avoid invalidaccess. This vulnerability is reachable via libraries such as ImageMagick, and this module provides the latest vector for Ghostscript.
Mitigation:
N/A